dhi.io/harbor-registryctl
2-debian-fips, 2-debian13-fips, 2-fips, 2.15-debian-fips, 2.15-debian13-fips, 2.15-fips, 2.15.2-debian-fips, 2.15.2-debian13-fips, 2.15.2-fips
sha256:9904843c915a2db50bb0663cbee4d1a7b4aa63548d8e2a0d1885c14d0e8d78a0
Manifest digest:sha256:3170df7cd0a029c66fc6b0b68b993d0ea1d133a0f43e617538077154eeec3953
Size
17.37 MB
Last pushed
5 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/harbor-registryctl:2-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/harbor-registryctl:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/harbor-registryctl@sha256:3ad762197233da671c2ae027143280f36eb25693f158b431c86f090500e2a214 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/harbor-registryctl@sha256:b0541e5d8827e6b7c55d8ce04e691bd31d447ccc3cac3533c3d38e1d2e815ab9 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/harbor-registryctl@sha256:68fa0af1ff41419ac6254d1e49bbb4350fc4538e4413156b6ad4dcb80fe92551 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/harbor-registryctl@sha256:e1dd96b625ac1d5fcbcede103216d7d16c92c2c83ee698886c392ac2ba644680 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/harbor-registryctl@sha256:53adb81c4a534107a3957a8c8da8e10f2b33496fbdae4aff9237ccb96621be93 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/harbor-registryctl@sha256:fd63b9f29bbc30043b6a269ba2cd33acd635ffd22a4b587067e8aed6caaf41f9 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/harbor-registryctl@sha256:ea640ea1e60262a0832290a5f48adbf666fca386f2762490d825609e09003884 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/harbor-registryctl@sha256:dd9aa483fc5838b1c05b72bbbed91480817cc025c0e50d402375104a7755e15a |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/harbor-registryctl@sha256:c4d7fa232c7817074aa0e785f6e5c7927367282fb50e49501709d94e465bf081 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/harbor-registryctl@sha256:93fe2eaabf7609aac53c93242c99b505fa7240e63396affc4647e0990211b870 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/harbor-registryctl@sha256:b5fe98e500dee0a162be548abcfd1602b0494aa27cc15e93d02855a7233b403d |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/harbor-registryctl@sha256:30c693ceed1770a37911010271db934e13a156793afc14261028dc45ce5f919c |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/harbor-registryctl@sha256:7023de3db0b7377b5ca7c0500878a38a8365cb2fba8613520dff821d69459564 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/harbor-registryctl@sha256:0ea05dcd2ffd0f6b87700098f5859c2c2777ab011356c1897d52ac56ca1acbab |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/harbor-registryctl@sha256:4e91ef449849a17438c4ece2e42259d22c12c9c5b9676bb98b027af405296e3d |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/harbor-registryctl@sha256:fbed5130740d42ec5c0deeef43407f616b41fc1b50f9762dbe85557656234640 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/harbor-registryctl@sha256:938de1b33742e341357962ade38d945e232d860b467bc513e137a0372c862823 |